Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 871 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105210] ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted…
ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified. Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, a…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105212] ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Logi…
ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified. Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing exist…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-105215] ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1…
ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, w…
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en StylemixThemes Cost Calculator Builder expone datos sensibles
Se ha identificado una vulnerabilidad de inserción de información sensible en el plugin StylemixThemes Cost Calculator Builder (versiones hasta 4.0.17) que permite a atacantes recuperar datos confidenciales enviados a través del formulario. Afecta principalmente a sitios WordPress en México y LATAM que utilizan este complemento para cotizadores en línea. La exposición de datos de clientes, presupuestos y información empresarial representa un riesgo alta de cumplimiento normativo.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad XSS almacenado alta en Kadence Blocks para Gutenberg (CVE-2026-103354)
Se ha identificado una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el plugin Gutenberg Blocks by Kadence Blocks (versiones hasta 3.7.11.1) que permite a atacantes inyectar código malicioso en páginas web generadas. Esta falla afecta sitios WordPress en México y Latinoamérica que utilizan este plugin para diseño de contenidos, exponiendo datos de usuarios y comprometiendo la integridad de los sitios. Con puntuación CVSS 7.1, constituye una amenaza moderada-alta que requiere atención inmediata.
M Crítico vulnerabilidad
Hace 5 días
Inyección SQL ciega crítica en Unlimited Elements for Elementor (CVSS 9.3)
Vulnerabilidad de inyección SQL en el plugin Unlimited Elements for Elementor (versiones hasta 2.0.20) permite a atacantes ejecutar consultas maliciosas contra bases de datos de sitios WordPress. Afecta principalmente a agencias digitales y empresas en LATAM que utilizan este plugin de diseño para construir landing pages y portales. El impacto es crítico: acceso no autorizado a datos sensibles, robo de credenciales y compromiso total del sitio.
M Crítico vulnerabilidad
03/10/2026
Vulnerabilidad crítica en Beaver Builder permite ejecución de código en sitios WordPress
El plugin Beaver Builder Page Builder para WordPress (versiones hasta 2.11.0.5) contiene una vulnerabilidad de ejecución arbitraria de shortcodes que permite a atacantes no autenticados ejecutar código malicioso. Afecta directamente a miles de sitios web de empresas, agencias y e-commerce en México y LATAM que utilizan este constructor visual popular. La falta de validación adecuada en la función do_shortcode expone datos sensibles y control total del sitio.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/10/2026
Vulnerabilidad de omisión de autorización en plugin Nelio Content para WordPress (CVE-2026-94505)
El plugin Nelio Content – Editorial Calendar & Social Media Auto-Posting para WordPress es vulnerable a omisión de autorización en versiones hasta 4.5.0. Atacantes autenticados con acceso de contribuidor pueden eliminar permanentemente contenido de redes sociales reutilizables. Afecta especialmente a agencias de marketing digital y empresas de comunicación en LATAM que usan WordPress con este plugin.
M Alto vulnerabilidad
03/10/2026
Vulnerabilidad alta en Simple Membership para WordPress permite modificación no autorizada de datos
El plugin Simple Membership para WordPress (versiones hasta 4.8.3) contiene una vulnerabilidad que permite a atacantes no autenticados modificar datos y acceder a información sensible a través de los endpoints resend-activation y email-activation. La falta de validación de autenticación, nonce y permisos en estas funciones expone a miles de sitios WordPress en LATAM que utilizan este plugin gratuito para gestionar membresías.
M Alto vulnerabilidad
03/10/2026
[CVE-2026-88783] The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed H…
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administr…
M Alto vulnerabilidad
03/10/2026
[CVE-2026-91078] The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the…
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be changed before use, and it authenticates its public POS login endpoint on that PIN alone with no identity or capability check, allowing unauthenticated attackers to obtain a privileged POS session and thereby read customer and site-user personal…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-95102] WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate chargin…
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82039] UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu…
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-51916] TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_use…
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de bypass de autenticación en YesWiki anteriores a 4.6.7
YesWiki antes de la versión 4.6.7 contiene una vulnerabilidad de bypass de autenticación en la bandeja de entrada ActivityPub que no vincula correctamente la firma HTTP verificada con el actor de la actividad. Atacantes no autenticados pueden utilizar cualquier par de claves ActivityPub para enviar actividades Delete o Update firmadas, permitiendo eliminar o sobrescribir entradas federadas de otros actores, especialmente en sistemas colaborativos y wikis corporativas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104431] Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to s…
Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script verification. Attackers can send non-standard high-sigop P2SH transactions that reach CachedFfiTransaction::is_valid() before standardness checks, saturating the verifier buffer and rendering the node unresp…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-94541] The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization b…
The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to exfiltrate password-reset URLs for arbitrary users, including administrators, mirrored into the p…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97663] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 5.122.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This require…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97342] The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-…
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-97637] The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Coo…
The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()…